System and method for virtual information cards
    1.
    发明授权
    System and method for virtual information cards 有权
    虚拟信息卡的系统和方法

    公开(公告)号:US08561172B2

    公开(公告)日:2013-10-15

    申请号:US12201754

    申请日:2008-08-29

    IPC分类号: G06F12/00 G06F15/16

    CPC分类号: G06F15/16 H04L9/00

    摘要: A client includes a card selector, and receives a security policy from a relying party. If the client does not have an information card that can satisfy the security policy, the client can define a virtual information card, either from the security policy or by augmenting an existing information card. The client can also use a local security policy that controls how and when a virtual information card is defined. The virtual information card can then be used to generate a security token to satisfy the security policy.

    摘要翻译: 客户端包括卡选择器,并从依赖方接收安全策略。 如果客户端没有可以满足安全策略的信息卡,则客户端可以从安全策略中或通过扩充现有信息卡来定义虚拟信息卡。 客户端还可以使用本地安全策略来控制虚拟信息卡的定义方式和时间。 然后可以使用虚拟信息卡来生成安全令牌以满足安全策略。

    System and method for enabling automated run-time input to network bootstrapping processes
    2.
    再颁专利
    System and method for enabling automated run-time input to network bootstrapping processes 有权
    用于启用自动运行时输入到网络引导过程的系统和方法

    公开(公告)号:USRE44299E1

    公开(公告)日:2013-06-11

    申请号:US12756653

    申请日:2010-04-08

    申请人: Drake Backman

    发明人: Drake Backman

    IPC分类号: G06F15/177 G06F1/24

    CPC分类号: G06F9/4416

    摘要: A system and method are provided for enabling runtime parameter value input into a computer device during a network bootstrapping process. The system and method may use a memory block to store values needed at runtime that are ordinarily input by a user. A configuration file having one or more macros included may be stored at a TFTP server. A first bootstrap program is loaded on the computer device to initialize a memory block with the name of the configuration file to be used by the computer device during booting and the values for any macros included in the configuration file. The first bootstrap program then calls a second bootstrap program to parse the memory block and/or the configuration file in order to use the contents of the configuration file to boot the computer device. Using macros in the configuration files enable the same configuration file to be used by devices with differing booting needs.

    摘要翻译: 提供了一种系统和方法,用于在网络引导过程期间使运行时参数值输入计算机设备。 系统和方法可以使用存储器块来存储通常由用户输入的运行时所需的值。 具有一个或多个宏的配置文件可以存储在TFTP服务器。 在计算机设备上加载第一个引导程序,以便在引导过程中使用要由计算机设备使用的配置文件的名称以及配置文件中包含的任何宏的值来初始化内存块。 第一引导程序然后调用第二引导程序来解析存储器块和/或配置文件,以便使用配置文件的内容来引导计算机设备。 在配置文件中使用宏可以启用具有不同引导需求的设备使用相同的配置文件。

    System and method for creating platform-specific self-extracting client packages using a production server
    3.
    发明授权
    System and method for creating platform-specific self-extracting client packages using a production server 有权
    使用生产服务器创建特定于平台的自解压客户端软件包的系统和方法

    公开(公告)号:US08332841B2

    公开(公告)日:2012-12-11

    申请号:US11954797

    申请日:2007-12-12

    IPC分类号: G06F9/445

    CPC分类号: G06F8/71 G06F8/61

    摘要: System and method for creating platform-specific self-extracting client packages using a production server are described. In one embodiment, the method comprises compiling a source file on a first build server comprising a first computing platform to produce a first executable seed file for the first computing platform and compiling the source file on a second build server comprising a second computing platform to produce a second executable seed file for the second computing platform; and providing the first and second executable seed files to a production server comprising the first computing platform. The production server uses the first executable seed file to create a first client package and a second client package, wherein the first client package is designed to be installed and execute on a first workstation running on the first computing platform and the second client package is designed to be installed and execute on a second workstation running on the second computing platform.

    摘要翻译: 描述使用生产服务器创建特定于平台的自解压客户端包的系统和方法。 在一个实施例中,该方法包括在包括第一计算平台的第一构建服务器上编译源文件,以产生用于第一计算平台的第一可执行种子文件,并且在第二构建服务器上编译源文件,该构建服务器包括第二计算平台以产生 用于第二计算平台的第二可执行种子文件; 以及将第一和第二可执行种子文件提供给包括第一计算平台的生产服务器。 所述生产服务器使用所述第一可执行种子文件来创建第一客户端包和第二客户端包,其中所述第一客户端包被设计为在第一计算平台上运行的第一工作站上安装和执行,并且所述第二客户端包被设计 在第二个计算平台上运行的第二个工作站上进行安装和执行。

    Single sign on with proxy services
    4.
    发明授权
    Single sign on with proxy services 有权
    单点登录代理服务

    公开(公告)号:US08327426B2

    公开(公告)日:2012-12-04

    申请号:US11444944

    申请日:2006-06-01

    IPC分类号: H04L29/06

    摘要: Techniques for proxing services with a single sign on are provided. A principal authenticates to a first identity service. The first identity service is in a trusted relationship with a second identity service. An authentication request is sent to the second identity service and the request includes an authentication response supplied by the first identity service in response to successful authentication of the principal to the first identity service. In response to the authentication request and the accompanying response, the principal is authenticated for access to the second identity service. Furthermore, targeted services accessible to the second identity service are proxied from and to the principal during interactions between the principal and an external service of that principal.

    摘要翻译: 提供使用单点登录服务的技术。 主体认证第一身份服务。 第一个身份服务与第二个身份服务处于可信赖的关系中。 认证请求被发送到第二身份服务,并且请求包括由第一身份服务提供的认证响应,以响应对第一身份服务的主体的成功认证。 响应于认证请求和伴随的响应,主体被认证用于访问第二身份服务。 此外,第二身份服务可访问的目标服务在委托人的主体和外部服务之间的交互中由委托人代理。

    Construction, manipulation, and comparison of a multi-dimensional semantic space
    5.
    发明授权
    Construction, manipulation, and comparison of a multi-dimensional semantic space 有权
    多维语义空间的构建,操纵和比较

    公开(公告)号:US08131741B2

    公开(公告)日:2012-03-06

    申请号:US11929678

    申请日:2007-10-30

    IPC分类号: G06F7/00 G06F17/30

    摘要: A directed set can be used to establish contexts for linguistic concepts: for example, to aid in answering a question, to refine a query, or even to determine what questions can be answered given certain knowledge. A directed set includes a plurality of elements and chains relating the concepts. One concept is identified as a maximal element. The chains connect the maximal element to each concept in the directed set, and more than one chain can connect the maximal element to any individual concept either directly or through one or more intermediate concepts. A subset of the chains is selected to form a basis for the directed set. Each concept in the directed set is measured to determine how concretely each chain in the basis represents it. These measurements for a single concept form a vector in Euclidean k-space. Distances between these vectors can be used to determine how closely related pairs of concepts are in the directed set.

    摘要翻译: 可以使用定向集来建立语言概念的上下文:例如,帮助回答问题,改进查询,甚至确定给定某些知识可以回答哪些问题。 定向集包括与概念相关联的多个元素和链。 一个概念被确定为最大元素。 这些链将最大元素连接到定向集中的每个概念,并且多于一个链可以直接或通过一个或多个中间概念将最大元素连接到任何单个概念。 选择链的子集以形成定向集的基础。 测量定向集中的每个概念,以确定每个链中每个链的具体含义。 单个概念的这些测量在欧几里德k空间中形成一个向量。 这些向量之间的距离可用于确定相关的概念对在定向集中的密切程度。

    Provisioning users to multiple agencies
    6.
    发明授权
    Provisioning users to multiple agencies 有权
    将用户配置到多个机构

    公开(公告)号:US08117650B2

    公开(公告)日:2012-02-14

    申请号:US11906941

    申请日:2007-10-04

    IPC分类号: G06F7/04

    CPC分类号: G06Q10/10 G06Q20/3821

    摘要: Apparatus and methods are described for providing employee cards to employees, such as PIV cards to federal employees, including provisioning the employees to a more than one agency (and more than one card) without requiring multiple instances of enrolling and adjudicating the employee. Representatively, a sponsor enters information about the employee into a computer-displayed form (e.g., web-based). Biometric identity information is collected for the employee, but if such has already begun or is complete for at least a first agency, the collected information is used for a second agency without redundant collection. In the event an adjudication level of the first agency is at least as stringent as it is for the second agency, the employee is eligible to receive an employee card for the second agency, in addition to an employee card for the first agency.

    摘要翻译: 描述了用于向雇员提供员工卡(例如向联邦雇员提供的PIV卡)的装置和方法,包括将员工提供给多个机构(和多于一个卡),而不需要多次登记和裁定员工的实例。 代表性地,赞助者将关于雇员的信息输入到计算机显示的形式(例如,基于网络)。 为员工收集生物识别信息,但如果已经开始或至少为第一个机构完成了生物识别信息,则收集的信息将用于第二个机构,而不需要进行多余的收集。 如果第一代理机构的裁决级别至少与第二代理机构的审判级别相同,除了第一代理机构的员工卡外,该员工有资格获得第二机构的员工卡。

    Techniques for securing content in an untrusted environment
    7.
    发明授权
    Techniques for securing content in an untrusted environment 失效
    在不受信任环境中保护内容的技术

    公开(公告)号:US08731201B2

    公开(公告)日:2014-05-20

    申请号:US12957336

    申请日:2010-11-30

    IPC分类号: H04L9/00 H04L9/08

    CPC分类号: G06F21/6218

    摘要: Techniques for securing content in an untrusted environment are provided. Content is encrypted and stored with a content delivery service in an encrypted format. Encrypted versions of a content encryption/decryption key and a first key are also housed and distributed by the content delivery service. The first key is used to decrypt the encrypted version of the content encryption/decryption key. The content delivery service is unaware of the content encryption/decryption key and the first key; and the content held by the content delivery service is encrypted with the content encryption/decryption key. Principals securely share, create, manage, and retrieve the encrypted versions of the content encryption/decryption key and the first key from the content delivery service using secure communications. The encrypted content is obtainable via insecure communications from the content delivery service.

    摘要翻译: 提供了在不受信任的环境中保护内容的技术。 内容被加密并以加密格式的内容传送服务存储。 内容加密/解密密钥和第一密钥的加密版本也由内容传递服务容纳和分发。 第一个密钥用于解密内容加密/解密密钥的加密版本。 内容传递服务不知道内容加密/解密密钥和第一密钥; 并且用内容加密/解密密钥加密由内容传送服务保存的内容。 校长使用安全通信安全地共享,创建,管理和检索内容加密/解密密钥的加密版本以及内容传送服务中的第一个密钥。 加密的内容可以通过来自内容传送服务的不安全通信获得。

    Light-weight multi-user browser
    8.
    发明授权
    Light-weight multi-user browser 有权
    轻便多用户浏览器

    公开(公告)号:US08676973B2

    公开(公告)日:2014-03-18

    申请号:US11370516

    申请日:2006-03-07

    申请人: Scott A. Isaacson

    发明人: Scott A. Isaacson

    IPC分类号: G06F15/173 G06F15/16

    摘要: A multi-user web browser is stored on a computer. The multi-user web browser permits more than one user to create and use a browser user account without requiring different users to log into different operating system user accounts. Instead, a browser user can log into the multi-user browser by providing a browser user name and browser password associated with the browser user name. This enables the multi-user web browser to support multiple users from within a single operating system user account.

    摘要翻译: 多用户网络浏览器存储在计算机上。 多用户Web浏览器允许多个用户创建和使用浏览器用户帐户,而不需要不同的用户登录到不同的操作系统用户帐户。 相反,浏览器用户可以通过提供与浏览器用户名相关联的浏览器用户名和浏览器密码来登录到多用户浏览器。 这使得多用户Web浏览器能够在单个操作系统用户帐户内支持多个用户。

    System and method for indicating usage of system resources using taskbar graphics
    9.
    发明授权
    System and method for indicating usage of system resources using taskbar graphics 有权
    使用任务栏图形指示系统资源的使用的系统和方法

    公开(公告)号:US08522247B2

    公开(公告)日:2013-08-27

    申请号:US11830534

    申请日:2007-07-30

    IPC分类号: G06F9/46

    摘要: System and method for a method for indicating relative usage of a computer system resource by a plurality of applications each running in an active window, wherein each active window is represented on a taskbar element by a taskbar button, are described. In one embodiment, the method comprises, for each of the active windows, determining a resource usage rate for the application running in the active window, the resource usage rate comprising a percentage of a total system resource usage for which the application accounts; subsequent to the determining, ranking the applications in order of the determined resource usage rates thereof; and redisplaying the taskbar buttons to indicate, via at least one display characteristic, the relative system resource usage rates of the applications.

    摘要翻译: 描述了用于通过在活动窗口中运行的多个应用来指示计算机系统资源的相对使用的方法的系统和方法,其中通过任务栏按钮在任务栏元素上表示每个活动窗口。 在一个实施例中,该方法包括针对每个活动窗口确定在活动窗口中运行的应用程序的资源使用率,资源使用率包括应用程序帐户所占用的系统资源总用量的百分比; 在确定之后,按照确定的资源使用率的顺序对应用进行排序; 并重新显示任务栏按钮,以通过至少一个显示特征指示应用程序的相对系统资源使用率。

    Method and mechanism for vending digital content
    10.
    发明授权
    Method and mechanism for vending digital content 有权
    售卖数字内容的方法和机制

    公开(公告)号:US08145570B2

    公开(公告)日:2012-03-27

    申请号:US11852502

    申请日:2007-09-10

    IPC分类号: G06F21/00 G06F15/16

    摘要: An Internet Box Office (IBO) system and technique vends digital content via a computer network, such as the Internet. The IBO system comprises a viewing system that cooperates with a Digital Rights Management system and various deployment enhancements within the Internet to provide an infrastructure that facilitates access to digital content in a manner that comports with copyright law and the control of intellectual property by the copyright owner. The IBO system enables a content copyright owner to retain control of its intellectual property while allowing a consumer to have transparent access to the copyright-protected content via the network. To that end, the IBO system operates to download and stage the copyrighted digital content on the viewing system of a consumer.

    摘要翻译: 互联网办公室(IBO)系统和技术通过诸如因特网之类的计算机网络来发送数字内容。 IBO系统包括与数字版权管理系统协作的观看系统以及因特网内的各种部署增强功能,以便提供一种便于以版权法和版权所有者控制知识产权的方式访问数字内容的基础设施 。 IBO系统使得内容版权所有者能够保持其知识产权的控制,同时允许消费者通过网络透明地访问受版权保护的内容。 为此,IBO系统运行以在消费者的观看系统上下载和播放受版权保护的数字内容。